Agent cell
Untrusted agent runtime runs in a Firecracker / FluxVM microVM, not only nspawn/bubblewrap on the host kernel.
- No raw secrets, no
CAP_NET_ADMIN, no host filesystem. - Admin plane is vsock only — no SSH to the agent.
- Optional
ttl_secondsfor throwaway research cells. - Host network pin: FluxVM TC
deny_udp+ gateway-only broker/proxy ports (confine.md). Guest Chromium never enforces policy. - Interim (fabric today): FluxVM sandbox + bubblewrap
InnerContainer::Strict, with a seccomp syscall filter (x86_64 only: an arm64 guest withstrictdoes not start). No Landlock layer, on purpose (see REMAINING.md). Details:agent-runtime/README.md, "inner containment". - Optional GPUs:
"gpus": Nin the agent manifest passes N free GPUs through to a QEMU cell (FluxVM picks them; needscell_backend: qemu; not withconfidential, a warm pool or hibernation). Tested against fakes only, not on a real GPU. Keep 0.1 target: Firecracker as the cell so escape still hits a hypervisor before the vault.